Install error on SCEP (system center endpoint protection) 4.7 on Windows 10 1703,1709

Sungpill Han
Sungpill Han used Ask the Experts™
on
I'm having issue to push out SCEP 4.7 to Windows 10 specifically version 1703 and 1709. I don't have issue with 1607.
It seems like version compatiblity issue. but don't know how to fix this.

-Where can I check compatible version of SCEP for Windows 10 1709 ? Is there any Microsoft website track and provide this?
-How can I update the installation file to the updated version?


When I push out SCEP to Windows 10 170x, it throws this error message in System Configuration;

"Cannot complete the System Center Endpoint Protection installation. An error has prevented the System Center Endpoint Protection setup wizard from completing successfully. Please restart your computer and try again. Error code:0x80070643. Fatal error during installation."


And in client's laptop log;

<![LOG[Sending ack to MTC for task {9BCF7827-E04F-4C3A-8D8C-B943316A2D7F}]LOG]!><time="10:49:46.529+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epmtchelper.cpp:98">
<![LOG[SCEP client is not present, SCEP client will be installed with the latest AM policy.]LOG]!><time="10:49:46.533+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentimpl.cpp:953">
<![LOG[Sending message to external event agent to disable notification]LOG]!><time="10:49:46.533+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentutil.cpp:960">
<![LOG[Sending message to endpoint ExternalEventAgent]LOG]!><time="10:49:46.533+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentutil.cpp:1175">
<![LOG[Disable Startup Signature Update equals to false.]LOG]!><time="10:49:46.561+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentimpl.cpp:467">
<![LOG[Add the Disable Startup Signature Update settings to policy xml successfully.]LOG]!><time="10:49:46.564+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentimpl.cpp:471">
<![LOG[Create Process Command line: "C:\windows\ccmsetup\SCEPInstall.exe" /s /q /policy "C:\windows\CCM\EPAMPolicy.xml".]LOG]!><time="10:49:46.564+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentutil.cpp:636">
<![LOG[Detail error message is : [EppSetupResult]
HRESULT=0x80070643
Description=Cannot complete the System Center Endpoint Protection installation. An error has prevented the System Center Endpoint Protection setup wizard from completing successfully. Please restart your computer and try again. Error code:0x80070643. Fatal error during installation.
]LOG]!><time="10:49:51.658+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentutil.cpp:435">
<![LOG[start to send State Message with topic type = 2001, state id = 4, and error code = 0x80070643]LOG]!><time="10:49:51.658+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentimpl.cpp:1337">
<![LOG[Start to send state message.]LOG]!><time="10:49:51.658+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentutil.cpp:1275">
<![LOG[Send state message successfully]LOG]!><time="10:49:51.667+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentutil.cpp:1277">
<![LOG[Save new state 4, error code -2147023293, detail message 'Cannot complete the System Center Endpoint Protection installation. An error has prevented the System Center Endpoint Protection setup wizard from completing successfully. Please restart your computer and try again. Error code:0x80070643. Fatal error during installation.' to registry SOFTWARE\Microsoft\CCM\EPAgent\State]LOG]!><time="10:49:51.667+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentimpl.cpp:235">
<![LOG[Failed to install EP client with exit code = 0x80070643.]LOG]!><time="10:49:51.667+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="3" thread="3296" file="epagentimpl.cpp:579">
<![LOG[Register a timer here to check whether definition get updated in 130 minutes.]LOG]!><time="10:49:51.667+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentimpl.cpp:1164">
<![LOG[Firewall provider is installed.]LOG]!><time="10:49:51.668+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentutil.cpp:808">
<![LOG[Installed firewall provider meet the requirements.]LOG]!><time="10:49:51.668+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentutil.cpp:829">
<![LOG[start to send State Message with topic type = 2001, state id = 4, and error code = 0x80070643]LOG]!><time="10:49:51.668+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentimpl.cpp:1337">
<![LOG[Skip sending state message due to same state message already exists.]LOG]!><time="10:49:51.673+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentutil.cpp:1268">
<![LOG[Endpoint is triggered by WMI notification.]LOG]!><time="10:49:51.674+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="9108" file="fepsettingendpoint.cpp:155">
<![LOG[Endpoint is triggered by WMI notification.]LOG]!><time="10:49:51.674+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="fepsettingendpoint.cpp:155">
<![LOG[File C:\windows\ccmsetup\SCEPInstall.exe version is 4.7.214.0.]LOG]!><time="10:49:51.677+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="9108" file="epagentutil.cpp:548">
<![LOG[Unable to query registry key (SOFTWARE\Microsoft\Microsoft Security Client), return (0x80070002) means EP client is NOT installed.]LOG]!><time="10:49:51.678+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="9108" file="epagentutil.cpp:181">
<![LOG[File C:\windows\ccmsetup\SCEPInstall.exe version is 4.7.214.0.]LOG]!><time="10:49:51.680+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentutil.cpp:548">
<![LOG[Unable to query registry key (SOFTWARE\Microsoft\Microsoft Security Client), return (0x80070002) means EP client is NOT installed.]LOG]!><time="10:49:51.680+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentutil.cpp:181">
<![LOG[Endpoint is triggered by message.]LOG]!><time="10:57:05.019+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="9556" file="fepsettingendpoint.cpp:59">
<![LOG[File C:\windows\ccmsetup\SCEPInstall.exe version is 4.7.214.0.]LOG]!><time="10:57:05.044+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="9556" file="epagentutil.cpp:548">
<![LOG[Unable to query registry key (SOFTWARE\Microsoft\Microsoft Security Client), return (0x80070002) means EP client is NOT installed.]LOG]!><time="10:57:05.044+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="9556" file="epagentutil.cpp:181">
<![LOG[Re-apply EP AM policy.]LOG]!><time="10:57:05.044+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="9556" file="fepsettingendpoint.cpp:108">
<![LOG[Endpoint is triggered by WMI notification.]LOG]!><time="10:57:05.673+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="fepsettingendpoint.cpp:155">
<![LOG[Firewall provider is installed.]LOG]!><time="10:57:05.675+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="9556" file="epagentutil.cpp:808">
<![LOG[Installed firewall provider meet the requirements.]LOG]!><time="10:57:05.675+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="9556" file="epagentutil.cpp:829">
<![LOG[File C:\windows\ccmsetup\SCEPInstall.exe version is 4.7.214.0.]LOG]!><time="10:57:05.678+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentutil.cpp:548">
<![LOG[Unable to query registry key (SOFTWARE\Microsoft\Microsoft Security Client), return (0x80070002) means EP client is NOT installed.]LOG]!><time="10:57:05.678+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentutil.cpp:181">
<![LOG[Sending ack to MTC for task {9BCF7827-E04F-4C3A-8D8C-B943316A2D7F}]LOG]!><time="10:57:05.678+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epmtchelper.cpp:98">
<![LOG[SCEP client is not present, SCEP client will be installed with the latest AM policy.]LOG]!><time="10:57:05.683+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentimpl.cpp:953">
<![LOG[Sending message to external event agent to disable notification]LOG]!><time="10:57:05.683+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentutil.cpp:960">
<![LOG[Sending message to endpoint ExternalEventAgent]LOG]!><time="10:57:05.683+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentutil.cpp:1175">
<![LOG[Disable Startup Signature Update equals to false.]LOG]!><time="10:57:05.703+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentimpl.cpp:467">
<![LOG[Add the Disable Startup Signature Update settings to policy xml successfully.]LOG]!><time="10:57:05.707+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentimpl.cpp:471">
<![LOG[Create Process Command line: "C:\windows\ccmsetup\SCEPInstall.exe" /s /q /policy "C:\windows\CCM\EPAMPolicy.xml".]LOG]!><time="10:57:05.707+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentutil.cpp:636">
<![LOG[Detail error message is : [EppSetupResult]
HRESULT=0x80070643
Description=Cannot complete the System Center Endpoint Protection installation. An error has prevented the System Center Endpoint Protection setup wizard from completing successfully. Please restart your computer and try again. Error code:0x80070643. Fatal error during installation.
]LOG]!><time="10:57:10.058+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentutil.cpp:435">
<![LOG[EP State and Error Code didn't get changed, skip resend state message.]LOG]!><time="10:57:10.058+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentimpl.cpp:161">
<![LOG[State 4, error code -2147023293 and detail message are not changed, skip updating registry value]LOG]!><time="10:57:10.058+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentimpl.cpp:213">
<![LOG[Failed to install EP client with exit code = 0x80070643.]LOG]!><time="10:57:10.058+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="3" thread="3296" file="epagentimpl.cpp:579">
<![LOG[One timer is already created and running, skip the new timer here.]LOG]!><time="10:57:10.058+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentimpl.cpp:1155">
<![LOG[Firewall provider is installed.]LOG]!><time="10:57:10.061+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentutil.cpp:808">
<![LOG[Installed firewall provider meet the requirements.]LOG]!><time="10:57:10.061+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentutil.cpp:829">
<![LOG[start to send State Message with topic type = 2001, state id = 4, and error code = 0x80070643]LOG]!><time="10:57:10.061+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentimpl.cpp:1337">
<![LOG[Skip sending state message due to same state message already exists.]LOG]!><time="10:57:10.224+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentutil.cpp:1268">
<![LOG[Endpoint is triggered by WMI notification.]LOG]!><time="10:57:10.224+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3424" file="fepsettingendpoint.cpp:155">
<![LOG[Endpoint is triggered by WMI notification.]LOG]!><time="10:57:10.224+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="fepsettingendpoint.cpp:155">
<![LOG[File C:\windows\ccmsetup\SCEPInstall.exe version is 4.7.214.0.]LOG]!><time="10:57:10.224+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3424" file="epagentutil.cpp:548">
<![LOG[Unable to query registry key (SOFTWARE\Microsoft\Microsoft Security Client), return (0x80070002) means EP client is NOT installed.]LOG]!><time="10:57:10.224+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3424" file="epagentutil.cpp:181">
<![LOG[File C:\windows\ccmsetup\SCEPInstall.exe version is 4.7.214.0.]LOG]!><time="10:57:10.240+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentutil.cpp:548">
<![LOG[Unable to query registry key (SOFTWARE\Microsoft\Microsoft Security Client), return (0x80070002) means EP client is NOT installed.]LOG]!><time="10:57:10.240+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentutil.cpp:181">
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
System Administrator
Distinguished Expert 2018
Commented:
Please check if the clients are in pending reboot status. This may cause error 0x80070643.
Remove any existing security programs
Ensure that the Windows Installer service is running

Also check this article and this one.
It's found that if there's an antimalware software, SCEP management module remote installation will fail on Windows 10. Once Kaspersky was deleted, in about a hour, Windows Defender became active, then in about another 3  hours, SCEP was installed.

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial